net/sched: hhf: clamp quantum before hhf_change() to avoid overflow (CVE-2026-90073) | HOL Guard CVE